Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks
ID: 652bf5fc-190d-5d40-8dcc-6b56e604ffa6
STIX ID: report--652bf5fc-190d-5d40-8dcc-6b56e604ffa6
Feed Name: Microsoft Security
Microsoft identifies Moonstone Sleet, a distinct North Korean state‑aligned threat actor, that leverages trojanized open‑source tools (e.g., PuTTY), malicious npm packages, a weaponized game (DeTankWar), custom loaders (SplitLoader, YouieLoad), credential theft techniques, and a new FakePenny ransomware strain to pursue espionage and revenue generation; the report includes observed compromises, file hashes and domains, detection queries for Microsoft Defender XDR and Sentinel, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
